Procurement-ready artefacts shipped EU residency — Hetzner Nuremberg Self-hosted & hybrid available

Enterprise.
What procurement actually needs.

A short, honest page for security, legal and procurement teams. Every artefact below is downloadable today; every claim points at a file you can read or a control you can exercise. No fabricated certifications, no nine-fives we can't measure, no logos we don't have. For the architectural argument and per-framework status, see the Trust Center and Compliance.

Talk to a human, not a queue

Enterprise procurement, custom MSA edits, volume-pricing requests, EU invoice billing and self-hosted licensing all route to one address. Median first response is one business day, quoted against your purchase decision date, not a marketing wishlist.

01 — Procurement readiness

The artefacts your security review will ask for.

All of these are linked publicly — no NDA required for the templates. Counter-signed copies (DPA) are returned within two business days of an enterprise request.

Contracts
DPA · MSA
  • GDPR Article 28 DPA — public template at /legal/dpa. Counter-signed copy on request.
  • Master Service Agreement — base terms at /legal/terms. Custom MSA available for enterprise; redlines welcome.
Need a custom DPA edit or jurisdictional rider? legal@cloakapi.io
Security questionnaires
CAIQ · SIG-lite · custom RFP
  • CSA CAIQ-lite — pre-filled across 50 controls (CCM v4) at /legal/caiq. Updated on every architectural change.
  • SIG-lite — completed on request; turnaround typically three business days.
  • Custom RFP — send your spreadsheet to trust@cloakapi.io. We answer the questions we can and mark the rest "Not yet certified — see /compliance" rather than padding.
CAIQ source format is plain Markdown — diffable across versions.
Operational
Sub-processor list · BCP · security.txt
Subscribe to sub-processor change notifications: trust@cloakapi.io
Posture
Privacy · Insurance · Disclosure
  • Privacy posture — what we collect, what our gateway receives, retention windows, GDPR/UK-DPA basis at /legal/privacy.
  • Insurance summary — at /legal/insurance.html. No cyber or professional-liability policy is currently in force, so we cannot issue a certificate of insurance — the page states that plainly rather than implying cover we do not have.
  • Coordinated vulnerability disclosure — scope, safe-harbour, response SLAs at security.cloakapi.io.
02 — Deployment options

SaaS, self-hosted, or hybrid.

Three shapes of the same product. Pick the one that fits your data-residency constraints and your operations team's appetite. The privacy design — values the detectors identify are tokenised on the customer side before the request is sent — is the same in all three. A value the detectors miss is sent as written.

Default
SaaS
  • Hosting — Hetzner Nuremberg (DE). Gateway, signing infrastructure, billing metadata and staff audit log all stay in-region.
  • Edge — Cloudflare, EU data localisation pinned.
  • Onboarding — sign up, paste an API key, ship.
  • Best for — EU-domiciled customers who want zero ops overhead and Article 28 SCCs already wired in.
List pricing on /pricing — three flat gateway rates, no plan tiers or per-seat charges on the API. (The standalone Cloak apps are sold separately, on their own monthly plans.)
Customer-managed
Self-hosted
  • Distribution — signed Docker Compose bundle and Helm chart. Same binaries as SaaS.
  • Master KEK — generated on customer hardware (HSM-backed if present). CloakAPI is not given the KEK.
  • Updates — pull from a signed registry on a schedule you control. Air-gapped image bundles available.
  • Best for — regulated customers (health, finance, public sector) whose policy forbids any third-party hosting.
Self-hosted licensing is annual, paid in USD by invoice. Quote from enterprise@cloakapi.io.
Split control plane
Hybrid
  • Gateway — runs in your VPC (AWS, GCP, Azure, on-prem). Designed so that the plaintext-adjacent code paths run on customer hardware.
  • Signing keys — generated and stored customer-side; CloakAPI publishes only the public JWKS.
  • Control plane — billing, transparency-log archival, customer-portal SaaS-side, designed so that no plaintext or token material crosses the boundary.
  • Best for — large customers that want SaaS ergonomics for billing/admin but a hard residency boundary for the data path.
Reference architecture diagram on request.
02b — The central-proxy pattern

One proxy for the whole company.

Instead of adding the SDK to every app, run one central cloak-proxy on your own network — a server or container you control — and route all your apps through it (change one base_url). PII is tokenised on that proxy, inside your perimeter; the CloakAPI gateway receives the tokenised bytes. One place to configure detectors and privacy tiers, one place to update, every app protected.

Configure once
Central control
  • One config surface — detector policy, privacy tier and key management live on the proxy, not scattered across every service.
  • One update path — upgrade the proxy image on your schedule; every downstream app inherits it.
  • No per-app SDK — legacy services that can't take a library still get client-side tokenisation.
Inside your perimeter
Tokenised before egress
  • Plaintext stays home — tokenisation happens on the proxy on your own network; the gateway receives tokens in place of every value the proxy's detectors matched; a value they miss is sent as written.
  • Locked upstream — the official cloak-proxy routes only through the CloakAPI gateway (blind relay + metering), never direct to a provider.
  • Same receipts — calls can return a receipt your auditors verify offline when one was issued.
Pipeline: your apps → central proxy (tokenise) → CloakAPI gateway → provider. BYOK 5% or pooled keys 15%.
02c — Platform capabilities

The platform your rollout actually needs.

None of this is gated behind an "Enterprise plan": every account pays the same flat rates. Where a capability is not generally available yet, the item says so.

Organisations, teams & roles
Org / team RBAC
  • Organisations & members — invite your team, manage members, transfer ownership.
  • Role-based access — tenant roles (owner, billing, developer, read-only, auditor, member and more) gate every sensitive action.
  • Self-service lifecycle — org data deletion with a grace period; nothing locked behind a support ticket.
Identity & provisioning
SSO, SCIM & audit export
  • SAML 2.0 and OIDC single sign-on — in development (beta on request). There is no self-service setup in the portal yet; ask at enterprise@cloakapi.io.
  • SCIM 2.0 provisioning — in development (beta on request).
  • Audit-log export — download your organisation's audit log as CSV or an export bundle from the portal. Streaming to a SIEM is not available.
Compliance & events
GRC connectors & webhooks
  • Evidence push — connectors for Drata, Vanta and Sprinto (GRC integrations in the portal); beta, not yet confirmed against the vendors' live APIs. Other GRC platforms are not supported.
  • Signed webhooks — endpoint management, HMAC signing, secret rotation and replay are built; only the webhook.test event is sent today, the other event types are reserved.
  • Org-level compliance packs — retention, encryption-at-rest and control config attested in the receipt as an org-config hash.
03 — Support & availability

What we do today, and what we don't yet promise.

While the beta lasts, CloakAPI has no service level agreement: /legal/sla is the binding text, and it sets no uptime target and no service credits. Below is how support works today and what we measure, with no inflated "five nines" claim that we can't measure.

01
Support
  • How — email, Mon–Fri 09:00–17:00 CET, answered by a real person, not a ticket-routing queue.
  • Response targets — SEV-1 (service down) within 4 business hours, SEV-2 within 8 business hours, SEV-3 and general questions within 2 business days. Targets, not guarantees.
  • Out of hours — SEV-1 outages are worked as soon as detected; our alerting pages us outside business hours too, on a best-effort basis.
  • Same for everyone — every account gets the same direct line: no paid support tiers, no dedicated Slack or Teams channel, no named-contact add-on.
03
Enterprise agreements
  • Individual — enterprise agreements are individual contracts quoted by email, not a plan on the price list. Terms beyond the public documents are agreed in writing.
  • Custom — custom MSA, custom DPA edits, regional residency, VPC peering.
  • Best for — annual contracts, self-hosted, or hybrid deployments.

How uptime is defined and measured is documented at /legal/sla (sections 2 and 8); live status is at status.cloakapi.io. Where this page and /legal/sla differ, /legal/sla is the binding text.

04 — Buying motion

How an enterprise order gets placed.

A short, predictable path from first contact to signed contract. Median time-to-signature for the last few enterprise deals has been three to six weeks, gated almost entirely on your security review.

Contact & pricing

Email enterprise@cloakapi.io with a one-line description of your use case and rough volume (requests/month or seats). You'll get a custom quote within two business days. List pricing — three flat gateway rates, no plan tiers or per-seat charges on the API — is on /pricing.

Contracting

Custom MSA available; redlines welcome. DPA counter-signed within two business days of an enterprise request. Order forms are short — one schedule per environment, one per region.

Billing

Bank transfer and invoice billing in USD for annual orders above $25,000. Card and Stripe-tokenised payment for smaller commitments. Net-30 standard; net-60 on enterprise terms.

Security review

CAIQ-lite, SIG-lite, custom questionnaires, audit-letter requests and architecture reviews all go through trust@. Median turnaround on a completed CAIQ: three business days.

05 — What's verifiable today

You don't have to take our word for it.

Most enterprise vendors hand you a marketing PDF. CloakAPI hands you verification tools. Gateway responses can carry a signed receipt that an auditor can check offline when one is issued. The JSONL transparency feed shows the latest published tenant seed state, not receipt events or the full seed-rotation history. A separate Merkle API exposes proofs for recorded content-free events; leaf writes are best-effort, so these surfaces do not prove that every change was recorded.

Receipts

OpenReceipt: receipts use ECDSA P-256 / SHA-256 when they are issued, and can be hash-chained. The independent verifier at signedreceipts.org/verifier requires no CloakAPI account and does not send the receipt to us; it fetches our public keys and reports a pass/fail count (no receipt content) to api.cloakapi.io.

Per-tenant transparency log

Per-tenant JSONL feed of the latest published seed state for tenants that turn transparency on (off by default), not the full rotation history. The response carries a Gateway HMAC-SHA256 value, not an ES256 receipt signature. A separate Merkle API exposes content-free leaves, tree heads and inclusion/consistency proofs for recorded events. Leaf writes are best-effort; without a checkpoint held outside the Gateway, these surfaces cannot prove that every rotation was recorded or that the full history was not rewritten.

GET https://api.cloakapi.io/v1/transparency/seeds.jsonl